Isai
bf1dc2547f
[Rule Tunings] AWS SSM Command Document Created by Rare User ( #4848 )
...
* [Rule Tunings] AWS SSM Command Document Created by Rare User
## AWS SSM Command Document Created by Rare User
Rule executes as expected and has very few alerts in telemetry. However, it is one of the rules timing out occasionally.
- reduced execution window
- reduced new terms history window
- replaced wildcards with the flattened field in the query, which should improve performance
- replaced `aws.cloudtrail.user_identity.arn` with combination of `cloud.account.id` and `user.name` to account for Assumed Roles. This will only evaluate the role instead of each individual role session, which will improve performance.
- added investigation fields
- corrected tags
- added mitre technique
## AWS SSM `SendCommand` Execution by Rare User"
- added investigation fields
- added tag
* update pyproject.toml
update pyproject.toml version
2025-06-27 13:24:27 -04:00
..
2025-01-22 11:17:38 -06:00
2025-01-22 14:43:30 -06:00
2025-06-06 15:08:48 -04:00
2024-05-23 00:45:10 +05:30
2025-01-22 11:17:38 -06:00
2024-05-23 00:45:10 +05:30
2025-02-03 21:27:50 +05:30
2025-02-03 21:27:50 +05:30
2025-01-31 10:35:18 -05:00
2025-01-22 11:17:38 -06:00
2024-11-08 23:11:18 -05:00
2025-06-17 13:58:26 -04:00
2024-05-23 00:45:10 +05:30
2024-05-23 00:45:10 +05:30
2024-05-23 00:45:10 +05:30
2025-01-22 11:17:38 -06:00
2025-06-06 14:11:54 -04:00
2025-06-06 14:11:54 -04:00
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-06-17 13:19:22 -04:00
2025-01-22 11:17:38 -06:00
2025-03-20 20:32:07 +05:30
2025-06-17 14:51:18 -04:00
2025-02-03 21:27:50 +05:30
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-06-27 13:24:27 -04:00
2025-06-27 13:24:27 -04:00
2025-03-21 10:05:24 -04:00
2025-03-21 10:05:24 -04:00
2025-01-22 11:17:38 -06:00
2025-06-04 10:49:52 -04:00
2025-01-22 11:17:38 -06:00
2025-06-04 10:49:52 -04:00
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-02-20 10:53:36 -05:00
2025-01-22 11:17:38 -06:00
2025-03-20 20:32:07 +05:30
2024-05-23 00:45:10 +05:30
2024-05-23 00:45:10 +05:30
2024-05-23 00:45:10 +05:30
2025-01-22 11:17:38 -06:00
2025-06-04 10:49:52 -04:00
2025-01-22 11:17:38 -06:00
2024-11-05 02:09:05 -05:00
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-03-20 20:32:07 +05:30
2025-01-15 14:11:58 -05:00
2025-03-20 20:32:07 +05:30
2025-02-03 21:27:50 +05:30
2025-04-30 16:25:03 -04:00
2025-01-15 14:11:58 -05:00
2024-05-23 00:45:10 +05:30
2025-06-02 11:32:05 -04:00
2025-04-21 12:06:57 -04:00
2025-01-22 11:17:38 -06:00
2025-03-20 20:32:07 +05:30
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-01-15 13:55:45 -05:00
2024-06-19 10:04:41 -04:00
2024-06-19 10:04:41 -04:00
2024-06-19 10:04:41 -04:00
2024-06-19 10:04:41 -04:00
2024-06-19 10:04:41 -04:00
2021-07-21 15:24:56 -06:00
2025-04-21 11:02:14 -04:00
2025-06-06 14:11:54 -04:00
2025-02-03 23:03:20 +05:30
2025-01-22 11:17:38 -06:00
2025-04-24 15:39:51 -04:00
2025-03-20 20:32:07 +05:30
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-03-20 20:32:07 +05:30
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-03-20 20:32:07 +05:30
2025-03-20 20:32:07 +05:30
2025-03-20 20:32:07 +05:30
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-06-17 15:03:55 -04:00
2025-06-24 18:07:18 -04:00
2025-06-24 18:07:18 -04:00
2024-05-23 00:45:10 +05:30
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-01-22 11:17:38 -06:00
2025-02-20 10:05:40 -05:00